> On May 10, 2020, at 8:24 AM, Ron <ronljohnsonjr(at)gmail(dot)com> wrote:
>
> On 5/4/20 9:45 AM, Rui DeSousa wrote:
>>
>>
>> Using external authentication is an option too. i.e. using LDAP; disabling the account in LDAP means the user cannot login.
>
> That would be a disaster in an enterprise that has many systems, and uses LDAP/AD for account management.
>
> --
> Angular momentum makes the world go ‘round.
Hmm, enterprises do exactly that and once the account is disabled its disabled everywhere. Single sign-on is very common practice these days. I would agree if talking about a targeted specific system temporarily.